security

How we treat your data

What's in place today, what isn't yet, and where to send a questionnaire or a vulnerability report. No hand-waving.

status

What's in place, what isn't

  • in place per-workspace isolation by row-level policies · HMAC-verified Stripe, Shopify and Instagram webhooks · TLS in transit via Cloudflare · secrets outside code and images, with an age check · monthly backup-restore drill · no model training on customer data
  • not yet SOC 2 · SAML/SCIM · a published penetration test · EU data residency · customer-managed keys

questionnaires and DPAs: hello@selify.ai — we answer them; we don't yet have a self-service trust portal.

posture

How the platform is built

Workspace isolation

Every workspace-scoped table is filtered by workspace in application code and again by a row-level policy in Postgres, and every RPC that returns workspace data takes the workspace as a parameter. Realtime subscriptions are filtered server-side.

Webhook integrity

Stripe, Shopify and Instagram webhooks are verified against their signing secrets before any side effect runs. Billing writes are idempotent per event.

Secrets

Production secrets live in the runtime environment, never in code or container images; build-time variables are public-only. A scheduled job flags secrets that have gone unrotated too long.

Backups

Database backups are restored to a scratch instance on a monthly schedule to prove they work.

Inference

Text models run via API under Selify's account. Open-weights vision and imaging models (photo reading, virtual try-on, background removal) run on Selify's own on-demand GPU capacity, scaled to zero when idle. We do not fine-tune or train any model on customer data.

Authentication

Email and password sign-in with hosted auth; Shopify and social accounts connect over OAuth. Internal admin tooling sits behind a separate NDA and IP-allowlist gate.

Audit

Long-running operations execute as durable workflows with full event history; admin actions write to an audit log keyed by actor.

questions we hear

Frequently asked

Where is data stored?
Production data is stored with our infrastructure provider; edge caching is on Cloudflare's network. Ask us for the current region.
Who can see customer conversations?
Only the workspace's own members. Selify staff have no standing read access to DM or order content; support access is granted by the customer and logged.
Are prompts used to train models?
No. We do not fine-tune or train any model on customer data.
Do you support SSO?
Email/password today. SAML and SCIM are not built; tell us if they're a requirement.
Can we get a questionnaire or DPA answered?
Yes — hello@selify.ai. A mutual NDA usually precedes the full questionnaire.
disclosure

Report a vulnerability

Found something? Email hello@selify.ai. We read every report and reply to each one; researchers who want credit get it.

legal entity: Up Go Corp. (Ontario, Canada) · questionnaires and DPAs: hello@selify.ai